Scantide Guard Guide

RDP Brute-Force Protection for Windows Server

Protect RDP, RemoteApp and RDWeb by combining controlled exposure, Windows authentication evidence, realistic thresholds, trusted-source learning and application-aware monitoring.

Technical guideUpdated 25 September 2026Scantide Guard
Short answer: Protect RDP, RemoteApp and RDWeb by combining controlled exposure, Windows authentication evidence, realistic thresholds, trusted-source learning and application-aware monitoring.

Reduce direct RDP exposure first

Where possible, put RDP behind VPN, Remote Desktop Gateway, trusted network restrictions or another controlled access path. Guard adds host-level evidence and response for environments where RDP-related authentication remains reachable.

Use authentication events, not port assumptions

Guard monitors supported Windows authentication evidence rather than treating one TCP port as the whole application. That matters because RDP, RemoteApp and RDWeb can involve different Windows and IIS event paths. The collector needs enough context to identify the source and reason safely.

Do not compensate for aggressive thresholds with huge whitelists

A common design mistake is to block very quickly and then whitelist entire networks to reduce disruption. That creates blind spots. A better model combines realistic thresholds, explicit trust, successful-login learning and monitor-specific tuning.

Test RDWeb and RemoteApp after configuration changes

Certificates, authentication settings, proxies, gateways and IIS changes can alter what evidence is available. Generate controlled failed logins and verify that the expected source IP and username reach Guard before relying on automatic blocking.

Practical depth: examples, failure modes and what to verify

Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.

Current Scantide detail

Current Scantide source: Scantide Guard Product & Server Security Guides

Protect Windows Server from repeated RDP, IIS/RDWeb, Kerberos and SQL Server authentication attacks with deterministic monitoring and Windows Firewall blocking.

Current Scantide source: Scantide Guard for Windows Server

Scantide Guard is intended for Windows Server estates ranging from Windows Server 2008 R2 SP1 through current Windows Server releases. The product family includes Windows Server 2008 R2, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022 and Windows Server 2025. Server 2008 R2 uses the Legacy Guard implementation; later Windows Server versions use the modern Guard implementation.

Current Scantide source: RDP Brute Force Protection for Windows Server

Windows Security Event ID 4625 is a common failed-logon source. Guard also supports other trusted authentication evidence depending on the configured collector.

Current Scantide source: Scantide Guard Product & Server Security Guides

Scantide Guard is designed for mixed Windows Server environments including Windows Server 2008 R2 SP1, 2012 R2, 2016, 2019, 2022 and 2025. One unified Windows installer covers Guard and Datacenter, while automatically selecting Legacy Guard on Windows Server 2008 R2 SP1.

Current Scantide source: RDP Brute Force Protection for Windows Server

Internet-facing RDP services are continuously probed. Guard watches trusted Windows authentication evidence, correlates repeated failures and can block the source IP locally before it continues hammering the server.

Field experience from the archive

Historical source · JufCorp: Securing your servers, users and customers online

Use an automatic brute force prevention software ( I can recommend you some that can block attacks on RDWeb, RDP, Exchange Webmail, FTP, Citrix., basically anything that uses Windows Authentication or help you set it up if you like)

Brute force attacks Another method of rendering you server useless is to use a brute force attack on the usernames (sometimes also known as a "dictionary attack" ) .

Historical source · JufCorp: Increased hacking and bruteforce attacks .. And it will get worse

Easy to use, cheap and it's helped protect against 185 000 live brute force attacks around the world so far. Since July 15th!

Historical source · JufCorp: Brute force protection on Windows Server

Now, there are other ways of taking care of this problem and one is to use a brute force prevention software (which I do )

Anyhoo.. just a short post on the matter of brute force prevention on Windows and what it can do for yu.

Historical source · JufCorp: Syspeace first public month - 40 000+ brute force attacks blocked!

So far,our first public month.40 000+ brute force attacks successfully blocked and traced! #rdp #windowsserver #infosec http://t.co/KOlgoMLO -- Syspeace (@Syspeace)

Practical review checklist

Frequently asked questions

Can Guard protect RDWeb as well as direct RDP?

Yes, where the required Windows/IIS evidence is available. RDWeb has application-specific handling and should be tested after configuration changes.

Should I whitelist my office IP permanently?

Only when there is a clear operational reason. Successful-login learning and explicit trusted-source rules can be safer than broad permanent whitelisting.

Use the same principles with Scantide Guard

Scantide Guard combines preconfigured collectors, Custom Monitors, per-monitor policy, successful-login learning, explainable firewall enforcement and optional Datacenter management across Windows and Linux.

Explore Scantide Guard Custom Monitors Datacenter